<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:08:03 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-10615</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-10615</link>
      <description>bdu:2025-10615</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-10615</guid>
    </item>
    <item>
      <title>BREW-serveit-CVE-2024-47220 — HTTP Request Smuggling in ruby webrick</title>
      <link>https://cve.radiocsirt.org/vuln/brew-serveit-cve-2024-47220</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: serveit&lt;/p&gt;
&lt;p&gt;An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., &amp;#34;GET /admin HTTP/1.1\r\n&amp;#34; inside of a &amp;#34;POST /user HTTP/1.1\r\n&amp;#34; request. NOTE: the supplier&amp;#39;s position is &amp;#34;Webrick should not be used in production.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: serveit&lt;/p&gt;
&lt;p&gt;An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., &amp;#34;GET /admin HTTP/1.1\r\n&amp;#34; inside of a &amp;#34;POST /user HTTP/1.1\r\n&amp;#34; request. NOTE: the supplier&amp;#39;s position is &amp;#34;Webrick should not be used in production.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-serveit-cve-2024-47220</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0003 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0003</link>
      <description>certfr-2025-avi-0003</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0003</guid>
    </item>
    <item>
      <title>fkie_cve-2024-47220</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47220</link>
      <description>&lt;p&gt;Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-47220</guid>
    </item>
    <item>
      <title>GHSA-6f62-3596-g6w7 — HTTP Request Smuggling in ruby webrick</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6f62-3596-g6w7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: webrick&lt;/p&gt;
&lt;p&gt;An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., &amp;#34;GET /admin HTTP/1.1\r\n&amp;#34; inside of a &amp;#34;POST /user HTTP/1.1\r\n&amp;#34; request. NOTE: the supplier&amp;#39;s position is &amp;#34;Webrick should not be used in production.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: webrick&lt;/p&gt;
&lt;p&gt;An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., &amp;#34;GET /admin HTTP/1.1\r\n&amp;#34; inside of a &amp;#34;POST /user HTTP/1.1\r\n&amp;#34; request. NOTE: the supplier&amp;#39;s position is &amp;#34;Webrick should not be used in production.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6f62-3596-g6w7</guid>
    </item>
    <item>
      <title>OESA-2024-2226 — rubygem-webrick security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2226</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: rubygem-webrick, openEuler:22.03-LTS-SP4: rubygem-webrick, openEuler:22.03-LTS-SP3: rubygem-webrick, openEuler:20.03-LTS-SP4: rubygem-webrick, openEuler:22.03-LTS-SP1: rubygem-webrick&lt;/p&gt;
&lt;p&gt;WEBrick is an HTTP server toolkit that can be configured as an HTTPS server, a proxy server, and a virtual-host server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., &amp;amp;quot;GET /admin HTTP/1.1\r\n&amp;amp;quot; inside of a &amp;amp;quot;POST /user HTTP/1.1\r\n&amp;amp;quot; request. NOTE: the supplier&amp;amp;apos;s position is &amp;amp;quot;Webrick should not be used in production.&amp;amp;quot;(CVE-2024-47220)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: rubygem-webrick, openEuler:22.03-LTS-SP4: rubygem-webrick, openEuler:22.03-LTS-SP3: rubygem-webrick, openEuler:20.03-LTS-SP4: rubygem-webrick, openEuler:22.03-LTS-SP1: rubygem-webrick&lt;/p&gt;
&lt;p&gt;WEBrick is an HTTP server toolkit that can be configured as an HTTPS server, a proxy server, and a virtual-host server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., &amp;amp;quot;GET /admin HTTP/1.1\r\n&amp;amp;quot; inside of a &amp;amp;quot;POST /user HTTP/1.1\r\n&amp;amp;quot; request. NOTE: the supplier&amp;amp;apos;s position is &amp;amp;quot;Webrick should not be used in production.&amp;amp;quot;(CVE-2024-47220)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2226</guid>
    </item>
    <item>
      <title>RHSA-2025:1227 — Red Hat Security Advisory: Logging for Red Hat OpenShift - 5.9.11</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:1227</link>
      <description>&lt;p&gt;rsync: Info Leak via Uninitialized Stack Contents WEBrick: HTTP request smuggling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rsync: Info Leak via Uninitialized Stack Contents WEBrick: HTTP request smuggling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:1227</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3939-1 — Security update for ruby2.1</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3939-1</link>
      <description>&lt;p&gt;Security update for ruby2.1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ruby2.1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3939-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-47220</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47220</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:Pro:20.04:LTS: ruby2.7, Ubuntu:22.04:LTS: ruby-webrick, Ubuntu:24.04:LTS: ruby-webrick, Ubuntu:25.10: ruby-webrick&lt;/p&gt;
&lt;p&gt;Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:Pro:20.04:LTS: ruby2.7, Ubuntu:22.04:LTS: ruby-webrick, Ubuntu:24.04:LTS: ruby-webrick, Ubuntu:25.10: ruby-webrick&lt;/p&gt;
&lt;p&gt;Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47220</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0001 — IBM DB2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0001</link>
      <description>&lt;p&gt;Ein entfernter oder lokaler Angreifer kann mehrere Schwachstellen in IBM DB2 on Cloud Pak for Data ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu erzeugen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter oder lokaler Angreifer kann mehrere Schwachstellen in IBM DB2 on Cloud Pak for Data ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu erzeugen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0001</guid>
    </item>
  </channel>
</rss>
